Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

This rule detects potential bulk data exfiltration by monitoring for high volumes of file access events (FileAccessed, FileRead, FileModified) originating from the 'doc_helper.aspx' file-management web shell. It summarizes activity by device and user account, flagging instances where over 100 unique files are touched within a short timeframe, which is indicative of automated collection and exfiltration activities.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
000
Detects unauthorized attempts to dump the process memory of the Local Security Authority Subsystem Service (LSASS), a common technique used by attackers to harvest credentials from memory. This includes the use of legitimate diagnostic tools like procdump and comsvcs.dll, as well as the identification of resulting dump files in directory paths associated with LSASS.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
000
Detects unauthorized attempts to dump the process memory of the Local Security Authority Subsystem Service (LSASS), a common technique used by attackers to harvest credentials from memory. This includes the use of legitimate diagnostic tools like procdump and comsvcs.dll, as well as the identification of resulting dump files in directory paths associated with LSASS.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
000
Detects the use of non-standard, unusual, or potentially dangerous HTTP methods within Caddy web server logs, which may indicate reconnaissance, web application exploitation, or attempts to abuse server functionalities like WebDAV.
avatar
Anmol Vats@jerry
avatar
Detection Engineers
1 month ago
003
Detects the creation of an executable file named 'stealer.exe' within the Windows Startup folder. This activity is indicative of the Stealer/1.0 malware establishing persistence, ensuring execution upon user logon.
avatar
Subhankar H@Andrewsec57
avatar
Detections.ai Community
1 month ago
002
This rule detects potentially malicious process injection activities (CreateRemoteThreadApiCall, ProcessInjection, OpenProcessApiCall) targeting the Volume Shadow Copy Service process (vssvc.exe). It monitors for interactions originating from processes other than legitimate system processes (svchost.exe, services.exe) or vssadmin.exe, which is commonly associated with Volume Shadow Copy manipulation. Such activity often indicates attempts by malware or attackers to inject code into a critical system process to gain persistence, escalate privileges, or evade detection.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
1 month ago
405
This rule monitors process creation and execution events for specific filenames, command line strings, or folder paths that are associated with potentially suspicious or malicious activity. The rule looks for keywords such as ShieldBreak, RoguePlanet, LegacyHive, BlueHammer, RedSun, YellowKey, GreenPlasma, MiniPlasma, and UnDefend.
avatar
Adarsh Pandey@Pandeyadarsh
avatar
Detections.ai Community
1 month ago
3011
Detects instances where common web server applications (e.g., Apache, Tomcat, IIS, Nginx) or Java runtime environments spawn suspicious child processes like command shells (cmd.exe, powershell.exe, sh, bash) or network utilities (wget, curl). This behavior often indicates exploitation of a web vulnerability, such as Remote Code Execution (RCE), allowing an adversary to execute commands or download further malicious payloads.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
000
This rule detects potential command and control (C2) activity associated with the CurlRAT malware. It monitors for both the execution of 'curl' or 'curl.exe' processes with command lines containing known C2 domains, and network traffic originating from internal devices directed toward those same domains.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
000
This rule detects the presence of specific file hashes known to be associated with backdoored software builds, specifically related to recent supply chain compromises affecting South Korean software vendors (e.g., HAProxy builds). It monitors device file events, process initiation, and identity logon events to identify systems that have deployed, executed, or been accessed by these malicious binaries.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
000
Detects potential exploitation of PostgreSQL via logical decoding plugins, specifically targeting CVE-2026-6471. The rule monitors for the PostgreSQL server process spawning suspicious shell utilities or loading modules from locations outside of the expected PostgreSQL library or plugin directories, which is a common indicator of unauthorized code execution.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
000
Detects when the PostgreSQL service process (postgres.exe/postgres/postmaster) loads a shared library (.dll or .so) from a non-standard, user-writable directory (e.g., Temp, AppData, /tmp). This behavior is indicative of potential exploitation of vulnerabilities like CVE-2026-6471, where attackers attempt to load malicious plugins via unvalidated logical decoding plugin paths.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
000
This rule monitors the software inventory for outdated versions of the PostgreSQL database server. It identifies installations where the major and minor versions are below the threshold for current security releases (e.g., v18 < 6, v17 < 11, v16 < 15, v15 < 19, v14 < 24). Running outdated software increases the risk of exploitation of known vulnerabilities.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
100
This rule monitors the software inventory for outdated versions of the PostgreSQL database server. It identifies installations where the major and minor versions are below the threshold for current security releases (e.g., v18 < 6, v17 < 11, v16 < 15, v15 < 19, v14 < 24). Running outdated software increases the risk of exploitation of known vulnerabilities.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
100
This rule detects potentially malicious modifications to PostgreSQL configuration files or the creation of new library files (.so or .dll) by the PostgreSQL service process. It also flags when the PostgreSQL service process is initiated with command-line arguments referencing 'shared_preload_libraries', which can be abused to load arbitrary code or malicious extensions into the database engine.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
000
This rule detects potentially malicious modifications to PostgreSQL configuration files or the creation of new library files (.so or .dll) by the PostgreSQL service process. It also flags when the PostgreSQL service process is initiated with command-line arguments referencing 'shared_preload_libraries', which can be abused to load arbitrary code or malicious extensions into the database engine.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
000
Detects anomalous activity originating from PostgreSQL processes, including the spawning of shells (cmd, powershell, sh, bash), access to sensitive files (e.g., /etc/shadow, SSH keys), and file creation outside the standard PostgreSQL data directories, which is consistent with the abuse of SQL functionality like pg_read_file() or lo_export().
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
000
Detects anomalous activity originating from PostgreSQL processes, including the spawning of shells (cmd, powershell, sh, bash), access to sensitive files (e.g., /etc/shadow, SSH keys), and file creation outside the standard PostgreSQL data directories, which is consistent with the abuse of SQL functionality like pg_read_file() or lo_export().
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
000
This rule monitors the software inventory for outdated versions of the PostgreSQL database server. It identifies installations where the major and minor versions are below the threshold for current security releases (e.g., v18 < 6, v17 < 11, v16 < 15, v15 < 19, v14 < 24). Running outdated software increases the risk of exploitation of known vulnerabilities.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
100
This rule detects potentially malicious modifications to PostgreSQL configuration files or the creation of new library files (.so or .dll) by the PostgreSQL service process. It also flags when the PostgreSQL service process is initiated with command-line arguments referencing 'shared_preload_libraries', which can be abused to load arbitrary code or malicious extensions into the database engine.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
000
Detects modifications to the PostgreSQL configuration file 'pg_hba.conf' closely followed by a reload command (via pg_ctl or postgres processes). This behavior is indicative of an attacker attempting to modify authentication or connection access controls for a database.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
000
Page 441 of 1870